Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Lifecycle catalogue
SECURITY BULLETINIBMVERIFIED

PUBLISHER UPDATE · IBM-PRODUCTS-IBM-7289649

IBM-PRODUCTS-IBM-7289649 release notes and known issues

IBM Engineering Lifecycle Management products using IBM WebSphere Application Server Liberty is affected by an improper restriction of XML External Entity Reference vulnerability due to Apache CXF (CVE-2026-49875)

Scope: IBM Engineering Lifecycle Management Base. This update record adds version, fix and known-issue context. Its publication date is not a lifecycle boundary.

Summary

Official IBM security bulletin for IBM Engineering Lifecycle Management Base.

Known issues

Publisher statement

Not stated. The verified publisher record does not contain a known-issues statement.

Affected products and versions

Products

  • IBM Engineering Lifecycle Management Base

Affected versions

  • See the official publisher source for applicability.

Fixed versions or updates

  • No fixed version is stated in this record.

Recommended action

Review the official IBM bulletin and apply the listed remediation.

Related vulnerabilities

BlackTree CVE Intelligence

Official publisher evidence

IBMVERIFIED

IBM Engineering Lifecycle Management products using IBM WebSphere Application Server Liberty is affected by an improper restriction of XML External Entity Reference vulnerability due to Apache CXF (CVE-2026-49875)

Checked 28 Sep 2026. BlackTree preserves the last verified facts if a later source check is temporarily unavailable.

Open the official publisher source